CVE-2017-6498: Input Validation
An issue was discovered in ImageMagick 6.9.7. Incorrect TGA files could trigger assertion failures, thus leading to DoS.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u3Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:6.9.13.12+dfsg1-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6498?
CVE-2017-6498 has a severity level that can result in denial of service due to assertion failures.
How do I fix CVE-2017-6498?
To fix CVE-2017-6498, update ImageMagick to one of the patched versions: 8:6.9.11.60+dfsg-1.3+deb11u3, 8:6.9.11.60+dfsg-1.6+deb12u1, or 8:6.9.13.12+dfsg1-1.
Which versions of ImageMagick are affected by CVE-2017-6498?
CVE-2017-6498 affects ImageMagick versions earlier than 6.9.9.
Can exploiting CVE-2017-6498 lead to data breaches?
Exploiting CVE-2017-6498 primarily leads to denial of service rather than data breaches.
Where can I find more information about CVE-2017-6498?
For more information about CVE-2017-6498, check the official Debian security announcements.